Medium severity6.5NVD Advisory· Published Oct 11, 2026
CVE-2026-108728
CVE-2026-108728
Description
Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/executor/pkg/webhook/handler.gonvd
- github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.gonvd
- github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.gonvd
- hackmd.io/@haind/flyte-file-secret-pod-spec-disclosure-20261010nvd
- www.vulncheck.com/advisories/flyte-2.0.1-through-2.0.51-cleartext-secret-exposure-via-admission-webhooknvd
News mentions
0No linked articles in our index yet.